Latest CVE Feed
-
7.5
HIGHCVE-2004-1673
accountsettings_add.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allow remote attackers to create text files with arbitrary content via the accountid parameter.... Read more
Affected Products : web_mail- Published: Oct. 12, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0373
Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary code.... Read more
- Published: Oct. 07, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-0192
Directory traversal vulnerability in the parsing of Skin file names in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in an RJS filename.... Read more
- Published: Oct. 06, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0189
Stack-based buffer overflow in the HandleAction function in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to execute arbitrary code via a long ShowPreferences argument.... Read more
- Published: Oct. 06, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0188
Format string vulnerability in the SetBaseURL function in AtHoc toolbar allows remote attackers to execute arbitrary code via format string specifiers in an invalid URL that is recorded in the debug log.... Read more
Affected Products : athoc_toolbar- Published: Oct. 06, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0928
The Microsoft IIS Connector in JRun 4.0 and Macromedia ColdFusion MX 6.0, 6.1, and 6.1 J2EE allows remote attackers to bypass authentication and view source files, such as .asp, .pl, and .php files, via an HTTP request that ends in ";.cfm".... Read more
- Published: Oct. 05, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1349
gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.... Read more
- Published: Oct. 04, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1604
cPanel 9.9.1-RELEASE-3 allows remote authenticated users to chmod arbitrary files via a symlink attack on the _private directory, which is created when Front Page extensions are enabled.... Read more
Affected Products : cpanel- Published: Sep. 30, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-0190
Directory traversal vulnerability in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to delete arbitrary files via a Real Metadata Packages (RMP) file with a FILENAME tag containing .. (dot dot) sequences in a filename that ends with a ?... Read more
- Published: Sep. 29, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0692
The XPM parser in the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) via a malformed image file that triggers a null dereference, a different vulnerability than CVE-2004-0693.... Read more
Affected Products : qt- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0642
Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.... Read more
- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0558
The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a certain UDP packet to the IPP port.... Read more
Affected Products : cups- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0458
mah-jong before 1.6.2 allows remote attackers to cause a denial of service (server crash) via a missing argument, which triggers a null pointer dereference.... Read more
- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0691
Heap-based buffer overflow in the BMP image format parser for the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code.... Read more
Affected Products : qt- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0593
Sygate Enforcer 3.5MR1 and earlier passes broadcast traffic before authentication, which could allow remote attackers to bypass filtering rules.... Read more
- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-1050
Multiple buffer overflows in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via long command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.... Read more
Affected Products : db2- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-1049
IBM DB2 Universal Database 7 before FixPak 12 creates certain DMS directories with insecure permissions (777), which allows local users to modify or delete certain DB2 files.... Read more
Affected Products : db2_universal_database- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0928
Clearswift MAILsweeper before 4.3.15 does not properly detect and filter RAR 3.20 encoded files, which allows remote attackers to bypass intended policy.... Read more
Affected Products : mailsweeper- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0643
Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code.... Read more
- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0644
The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of service (infinite loop) via a certain BER encoding.... Read more
Affected Products : kerberos_5- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025